Know your vulnerabilities before someone else finds them.
Every computer in your business is running software with known, published weaknesses — the same lists attackers work from. This flat-fee vulnerability assessment finds every one of them on your machines and tells you, in plain English, which ones actually matter and what to fix first.
Delivered in 2 business days · No site visit · No contracts
How exposed is the software your business runs every day?
Check the programs you use. We'll show you how many security weaknesses were published for them in just the last 90 days — straight from the U.S. government's vulnerability database.
Select the software you use
Tap everything that runs in your office — most businesses use at least six of these.
Your report isn't generated by software. It's signed by a person.
Forestal Security is a founder-led security practice built for small businesses that need senior-level security answers without big-firm complexity.
I'm Edith Forestal. I've spent over a decade building and running technology companies — and today I develop AI-driven security tools used in more than a thousand analyses. My work spans vulnerability assessment, cloud and identity security, ethical hacking, and security automation, backed by a master's in cybersecurity and some of the industry's most rigorous certifications. When I assess your environment, I'm applying the same skills I use to defend high-stakes, heavily audited systems every day.
Every Exposure Report is reviewed, prioritized, and signed by me personally — and I'm the one on your findings call. No account managers, no offshore SOC, no upsell script.
Three steps. About an hour of your team's time, total.
No security knowledge required on your end. If someone in your office can double-click an installer, you can do this.
Check out online
Pick your tier below and pay securely by card. Within one business day you'll receive an email with a download link unique to your company and a 90-second video showing the install.
Your time: 5 minutesRun the installer on each computer
Anyone on your team can do it — it takes about a minute per machine and nothing needs to restart. The scanner reads the names and versions of installed software. It does not open your files, email, or documents.
Your time: ~1 minute per deviceGet your report
Within two business days: a written report covering every weakness found, which ones matter most, and a 30/60/90-day fix-it plan — plus an optional 30-minute call to walk through it together.
Your time: one coffeeA report you can actually read — and hand to your insurer or auditor.
Most vulnerability scans dump a spreadsheet of 400 acronyms on your desk. The Security Exposure Report is a vulnerability assessment written for the person who signs the checks.
Every weakness, found and counted
A complete inventory of known vulnerabilities across every device — scored by severity, matched to the exact software causing them.
What actually matters, in order
Weaknesses that criminals are actively exploiting right now (per the U.S. CISA Known Exploited Vulnerabilities catalog) are flagged first. Not everything urgent-sounding is urgent — the report tells you the difference.
A plain-English action plan
A 30/60/90-day roadmap your existing IT person (or IT company) can execute directly. Most fixes are free — they're updates that simply haven't been run.
Evidence for the people who ask
Cyber insurance applications, client security questionnaires, and auditors increasingly ask whether you assess vulnerabilities. This report is a dated, signed answer from a certified professional.
One flat price. No subscription required.
Priced by the number of devices in your business — computers, laptops, and servers. Not sure of your count? A close guess is fine; we'll confirm before the report is finalized.
- Full exposure report
- Prioritized fix-it plan
- 30-minute findings call
- Delivered in 2 business days
- Everything in Small office
- Findings grouped by location or department
- Server-specific risk review
- 60-minute findings call
- Examiner-ready documentation
- Mapped to your compliance framework
- Quarterly review available
- Scoped to your environment
The things every owner asks first.
Is the scanner safe? What does it actually see?
The scanner reads the list of installed programs and their version numbers, plus basic system information — the same list you'd see in your computer's own Settings app. It does not read your files, email, documents, or browsing. It runs quietly in the background and won't slow your machines down.
Do we have to keep it installed afterward?
No. After your report is delivered, you'll get simple removal instructions — or we can remove it remotely for you. If you later choose a quarterly review, it stays on so future reports can show your progress.
Who installs it — do you come on site?
No site visit needed. You'll get a download link and a short video; anyone on your team can run it in about a minute per computer. If you work with an outside IT company, forward them the email — they'll know exactly what to do.
Does it cover Windows and Mac?
Yes — Windows PCs, Windows servers, and Macs are all covered in one report.
Will you fix the problems too?
The report is designed so your existing IT person or IT company can do the fixes — most are routine software updates. If you don't have anyone, the findings call includes honest recommendations on getting the work done, including whether you need ongoing help at all.
Is this a full vulnerability assessment?
Yes. The Security Exposure Report is a complete vulnerability assessment of your Windows and Mac computers and servers: every device is scanned against the industry's published vulnerability databases (the same CVE data attackers use), findings are risk-ranked by severity and active exploitation, and you receive a prioritized remediation plan. It satisfies the annual vulnerability assessment requirement found in most cyber insurance applications.
How much does a vulnerability assessment cost?
Ours is a flat fee: $750 for up to 50 devices, $1,500 for up to 150. Comparable assessments from security firms typically run $2,000–$10,000, priced by hourly consulting rates. We keep the cost flat and low by automating the scanning and focusing the human expertise where it matters — analyzing, prioritizing, and explaining the findings.
Who performs the assessment?
Edith Forestal — CISSP, CISM, CEH, and SecurityX certified. With more than a decade of hands-on security experience running a technology company, he managed email authentication (SPF, DKIM, and DMARC), SSL/TLS certificates, patch management, software updates, backups and disaster recovery, vulnerability scanning and remediation, incident response, malware prevention, and security monitoring. Every report is personally reviewed and signed—not auto-generated, rubber-stamped, or forgotten.
Two business days from now, you could know exactly where you stand.
The weaknesses on your machines are already public knowledge. The only question is whether you find out from a report — or from an incident.
Get your Security Exposure ReportYou're early — and that works in your favor.
We're onboarding our first clients right now. Leave your email and we'll reach out within one business day with founding-client pricing (20% off) and your install link.
No payment now. No spam — one email from a real person.
You're on the list.
Expect an email from Edith within one business day.